CVE-2020-36402: High severity solidity vulnerability
Solidity 0.7.5 has a stack-use-after-return issue in smtutil::CHCSmtLib2Interface::querySolver. NOTE: c39a5e2b7a3fabbf687f53a2823fc087be6c1a7e is cited in the OSV "fixed" field but does not have a code change.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36402?
CVE-2020-36402 is classified as a medium severity vulnerability due to its potential to exploit a stack-use-after-return issue.
How do I fix CVE-2020-36402?
To mitigate CVE-2020-36402, it is recommended to upgrade to a newer version of Solidity that addresses this vulnerability.
What impact does CVE-2020-36402 have on Solidity 0.7.5?
CVE-2020-36402 can potentially allow attackers to exploit the stack-use-after-return condition, leading to unexpected behavior or crashes.
Is CVE-2020-36402 present in other versions of Solidity?
CVE-2020-36402 specifically affects Solidity version 0.7.5; other versions may not be impacted unless explicitly stated.
What components are affected by CVE-2020-36402?
CVE-2020-36402 affects the smtutil::CHCSmtLib2Interface::querySolver component in Solidity 0.7.5.